<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Techie Gyaaan &#187; Virus-AntiVirus</title>
	<atom:link href="http://techie.gyaaan.com/category/virus-antivirus/feed/" rel="self" type="application/rss+xml" />
	<link>http://techie.gyaaan.com</link>
	<description>Just another WordPress weblog</description>
	<lastBuildDate>Fri, 15 May 2009 15:19:40 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
		<item>
		<title>Sure fire way to kill Dipak Bhattrai Virus/Worm from your machine</title>
		<link>http://techie.gyaaan.com/sure-fire-way-to-kill-dipak-bhattrai-virusworm-from-your-machine/</link>
		<comments>http://techie.gyaaan.com/sure-fire-way-to-kill-dipak-bhattrai-virusworm-from-your-machine/#comments</comments>
		<pubDate>Mon, 05 May 2008 18:05:22 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Virus-AntiVirus]]></category>
		<category><![CDATA["Dipak Bhattrai"]]></category>
		<category><![CDATA[Internet Explorer]]></category>
		<category><![CDATA[Title bar]]></category>
		<category><![CDATA[Wscript]]></category>

		<guid isPermaLink="false">http://techie.gyaaan.com/?p=57</guid>
		<description><![CDATA[This virus mostly affects internet explorer and believe me its very very annoying to see some freak of nature&#8217;s name on your internet explorer title window. So here is the fix, The problem is due to a file called WScript.exe which is a program that runs in the background silently modifying the title of the [...]]]></description>
			<content:encoded><![CDATA[<p>This virus mostly affects internet explorer and believe me its very very annoying to see some freak of nature&#8217;s name on your internet explorer title window. So here is the fix,</p>
<p>The problem is due to a file called WScript.exe which is a program that runs in the background silently modifying the title of the IE window everytime you open it. It checks for the title of the program that is currently running and if its Internet Explorer then it adds the name &#8220;Dipak Bhattrai&#8221; to the the title before displaying it.</p>
<ol>
<li>Task Manager &#8211; Process &#8211; Kill Wscript.exe if it is running</li>
<li>Double click My computer. Click on Tools Menu -> Folder options -> View</li>
<li>If you are unable to view to do step 2. Then its due to another virus and here is the fix for that.
<ul>
<li>If you donot get the Show All Options ( maybe a because of this or another virus) follow the following step:<br />
                         Start -> Run -> Regedit (You must have admin rights to execute this command )<br />
HKEY_LOCAL_MACHINE -> SOFTWARE -> Microsoft -> Windows -> CurrentVersion -> Explorer -> Advanced -> Folder -> Hidden -> SHOWALL</p>
<p>Here check the registry value named &#8216;CheckedValue&#8217; (REG_DWORD) here right click on it and select &#8216;Modify&#8217; then set value to 1 and click &#8216;ok&#8217;. Close Registry Editor and check the Folder Option to verify this solution. If it is not there create it.
                    </li>
</ul>
</li>
<li>Now Navigate to C:\Windows\System32\.  Look for the file named VirusGuard.vbs ( This is the Culprit )</li>
<li>Delete the file VirusGuard.vbs (Not just sending it to the recycle bin. Shift + Delete)</li>
<li>Use HighJackThis to locate the registry entries and fix it ( Remove Invalid entires to IE )</li>
<li>Highjackthis can be downloaded <a href="http://www.trendsecure.com/portal/en-US/tools/security_tools/hijackthis">here</a></li>
<li>Reboot your system</li>
<li>some process will try to run VirusGuard.vbs script and gives you a error message</li>
<li>Start IE and just confirm it has removed the bloody name &#8220;Dipak bhattarai&#8221;</li>
<li>You might see a hyphen on ur IE. Fix it back to normal (&#8220;Windows Internet Explorer&#8221;) by using <a href="http://www.securitystronghold.com/gates/vbswg.aq.html">TrueSword.exe</a>
        </li>
</ol>
<p>If you want to know the email address of the guy who wrote this script in the first place leave your email in the comment. I promise that I&#8217;ll reply back to you with his email address.</p>
<p>Thanks to Harsh and Rama for the fix.</p>
]]></content:encoded>
			<wfw:commentRss>http://techie.gyaaan.com/sure-fire-way-to-kill-dipak-bhattrai-virusworm-from-your-machine/feed/</wfw:commentRss>
		<slash:comments>8</slash:comments>
		</item>
		<item>
		<title>Remove Adware Zeno from your computer</title>
		<link>http://techie.gyaaan.com/remove-adware-zeno-from-your-computer/</link>
		<comments>http://techie.gyaaan.com/remove-adware-zeno-from-your-computer/#comments</comments>
		<pubDate>Wed, 06 Feb 2008 19:00:29 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Virus-AntiVirus]]></category>
		<category><![CDATA[Antivirus]]></category>
		<category><![CDATA[Removal]]></category>
		<category><![CDATA[Virus]]></category>
		<category><![CDATA[Zeno]]></category>

		<guid isPermaLink="false">http://techie.gyaaan.com/?p=6</guid>
		<description><![CDATA[Adware-Zeno This is one annyoing spyware. Its relatively harmless but gets on your nerve. Step 1 Click on start -> Run Key in &#8220;regedit&#8221; Click on menu item &#8220;Edit&#8221; and on &#8220;Find&#8221; In the &#8220;Find What textbox&#8221; key in &#8220;qwdxrego.exe&#8221; and click on &#8220;Find Next&#8221; button Delete the entries that show up. Repeat the procedure [...]]]></description>
			<content:encoded><![CDATA[<li>Adware-Zeno</p>
<p>This is one annyoing spyware. Its relatively harmless but gets on your nerve.</p>
<p>Step 1</p>
<ul>
<li>Click on start -> Run </li>
<li>Key in &#8220;regedit&#8221; </li>
<li>Click on menu item &#8220;Edit&#8221; and on &#8220;Find&#8221; </li>
<li>In the &#8220;Find What textbox&#8221; key in &#8220;qwdxrego.exe&#8221; and click on &#8220;Find Next&#8221; button </li>
<li>Delete the entries that show up. </li>
<li>Repeat the procedure but this time search for a file called &#8220;ssysyq2r.exe&#8221; and delete any entries that show up. </li>
<p><em>Step 1-6 cleans up the registry. Now to delete the actual files.</em></p>
<li>Open explorer and navigate to c:\winnt\system32 or c:\windows\system32 </li>
<li>Click on the search button and search for &#8220;qwdxrego.exe&#8221;. Delete any files that show up in the search results. </li>
<li>Repeat step 8, this time search for &#8220;ssysyq2r.exe&#8221;. Delete any files that show up. </li>
<li>You’ll find a shortcut labeled “Zeno” (or zeno.lnk, including the extension) in your startup directory. Delete that too. </li>
<li>Restart your computer. </li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://techie.gyaaan.com/remove-adware-zeno-from-your-computer/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>

